Eufy Smart Lock Touch & Wi-Fi

Attention : *Confidentialité non incluse avec ce produit

Eufy Smart Lock Touch & Wi-Fi

Passé en revue le : 9 novembre 2022

|
Mozilla a effectué 8 heures de recherches
|

L’avis de Mozilla :

|
Vote du public : Moyennement flippant

To unlock Eufy's Smart Lock Touch & WiFi, all you have to do is give it the finger and use your fingerprint. Or open your door from far away with WiFi. Or use your Bluetooth connected phone to unlock the door when you're within 30 feet or so. You can also use the built-in keypad. Or even, gasp!, a physical key. So many ways to open your door! Wonder if saying, "Open Sesame" works too?

Que pourrait-il se passer en cas de problème ?

Smart locks are one of those connected devices that seem to worry lots of people. The pros: They offer a lot of convenience with multiple ways to unlock the door to your home, a way to track who comes and goes from your home, they can allow you give out a keypad number to people like a babysitter and then revoke that when they no longer need access, and they can help you make sure you locked your front door when your anxiety kicks in on vacation. The cons: They can be vulnerable to any number of things such as power outages, lost or compromised phones, ransomware attacks on the company who made your lock, product security vulnerabilities, WiFi and/or Bluetooth vulnerabilities, home hub vulnerabilities, bad software updates, data leaks, and more.

With all that said, how does Eufy’s Smart Lock Touch & WiFi stack up? This lock operates over WiFi and can be controlled from just about anywhere with the Eufy Security app. It also uses a fingerprint, which also seems generally safe, especially as Eufy stores your fingerprint data locally on the device rather than on the internet in the cloud where it could be more vulnerable. There's also a keypad and a key to unlock it. So, lots of ways to unlock this lock, if you need. We found no known security breaches of this smart lock.

Unfortunately, Eufy has had some significant security vulnerabilities with their security cameras. In June 2022, security experts foundthree security vulnerabilities in Eufy's Homebase 2 video storage and management device that could have allowed hackers to take control of the hub, control it remotely, or steal video footage. Eufy/Anker developed fixes for these security vulnerabilities and released them to users in a timely manner. And in May 2021, Eufy was forced to apologize for a bug that exposed the camera feeds of 712 users to strangers. Eufy said the glitch happened during a software update and “users were able to access video feeds from other users’ cameras.” Eufy said in a statement the glitch was fixed an hour after it was discovered.

So, the bad news is, Eufy’s security cameras have had some serious security issues. The good news is, Eufy as a company seems to have stepped up and immediately fixed these bugs and to get the updates out to their users quickly. While these security oopsies happened to their video cameras, not their smart locks, it’s a good reminder that software updates can go wrong, which wouldn’t be good for your smart lock.

On the privacy front, Eufy’s privacy policy says they can collect a good deal of personal information on you -- things like name, email, gender, birth date, location, device information, and more. And while Eufy says they don’t sell your personal information -- which is good -- they say they can use that information to show you ads from them and third party advertisers, which isn’t so good (but also pretty standard on the internet these days). They also say they can collect personal information on you from third parties who provide it to them, such as law enforcement authorities. This worries us a bit because the way that line in their privacy policy is written is rather vague and seems like it could leave open the possibility they could collect information on users from a variety of third parties, for example, data brokers.

What’s the worst that could happen? Well, it is a smart lock that can be unlocked with your fingerprint ID. We've watched enough movies to know there's always a chance someone could chop your finger off and use it to get in your home. We really hope that never happens to you. We also hope Eufy keeps tight security on their Eufy Security app so no one can hack it and unlock your home from far away. That would be bad.

Conseils pour vous protéger

  • Check out tips to ensure your smart lock safety
  • Maintain a strong door
  • Choose a secure access code
  • Set up two-factor authentication
  • Do not sign up with third-party accounts. Better just log in with email and strong password.
  • Chose a strong password! You may use a password control tool like 1Password, KeePass etc
  • Use your device privacy controls to limit access to your personal information via app (do not give access to your camera, microphone, images, location unless neccessary)
  • Keep your app regularly updated
  • Limit ad tracking via your device (eg on iPhone go to Privacy -> Advertising -> Limit ad tracking) and biggest ad networks (for Google, go to Google account and turn off ad personalization)
  • Request your data be deleted once you stop using the app. Simply deleting an app from your device usually does not erase your personal data.
  • When starting a sign-up, do not agree to tracking of your data if possible.
  • mobile

Ce produit peut-il m’espionner ? informations

Caméra

Appareil : Non

Application : Non

Microphone

Appareil : Non

Application : Non

Piste la géolocalisation

Appareil : Non

Application : Oui

Que peut-on utiliser pour s’inscrire ?

Quelles données l’entreprise collecte-t-elle ?

Comment l’entreprise utilise-t-elle les données ?

We ding this product for sharing personal data for advertisement and for combining users' data with data from third parties.

Eufy does not sell data. However, they share personal identifiers for advertisement purposes: "We do not Sell any personal information to third parties. In particular, we do not Sell the personal information of minors under 16 years of age. In the preceding 12 months, we have disclosed the following categories of personal information to the following categories of recipients: [...] Advertising networks, data analytics providers. - Personal Identifiers."

Eufy also combine users' data with data obtained from third parties: "We collect or obtain Personal Data from third parties who provide it to us (e.g., credit reference agencies; law enforcement authorities; etc.)."

Comment pouvez-vous contrôler vos données ?

We ding this product because it is not clear all users have the same rights to access and delete their data. Eufy specifically mentions the right to delete data only for users based in California.

"Subject to applicable law, you may have the following rights regarding the Processing of your Relevant Personal Data...."

Data retention policies for Eufy are rather confusing, however Eufy does promise to delete or anonymised data once they do not need it any more:
"Once the periods in paragraphs (1), (2) and (3) above, each to the extent applicable, have concluded, we will either:
- permanently delete or destroy the relevant Personal Data; or
- anonymize the relevant Personal Data."

Quel est l’historique de l’entreprise en matière de protection des données des utilisateurs et utilisatrices ?

Moyen

In June 2022, three security vulnerabilities were found in Eufy's Homebase 2 video storage and management device that could have allowed hackers to take control of the hub, control it remotely, or steal video footage. Eufy/Anker developed fixes for these secruity vulnerabilities and released them to users in a timely manner.

In May 2021, Eufy was forced to apologize for a bug that exposed the camera feeds of 712 users to strangers. Eufy said the glitch happened during a software update and “users were able to access video feeds from other users’ cameras.” Eufy said in a statement the glitch was fixed an hour after it was discovered.

Informations liées à la vie privée des enfants

Our Sites, products, or services are not directed to children under the age of 13. As a result, our Sites, products, or services do not request or knowingly collect personal information from individuals under the age of 13. If you are not 13 or older, you should not visit or use our Sites, products, or services .

Ce produit peut-il être utilisé hors connexion ?

Oui

Informations relatives à la vie privée accessibles et compréhensibles ?

Oui

Structured and concise

Liens vers les informations concernant la vie privée

Ce produit respecte-t-il nos critères élémentaires de sécurité ? informations

Oui

Chiffrement

Oui

Mot de passe robuste

Oui

Mises à jour de sécurité

Oui

Gestion des vulnérabilités

Oui

Politique de confidentialité

Oui

Le produit utilise-t-il une IA ? informations

Oui

Cette IA est-elle non digne de confiance ?

Impossible à déterminer

Quel genre de décisions l’IA prend-elle à votre sujet ou pour vous ?

The built-in AI reduces the number of false alerts you receive by intelligently differentiating people from objects. It has features like pet detection, and even crying detection.

L’entreprise est-elle transparente sur le fonctionnement de l’IA ?

Impossible à déterminer

Les fonctionnalités de l’IA peuvent-elles être contrôlées par l’utilisateur ou l’utilisatrice ?

Oui

*Confidentialité non incluse

Pour aller plus loin

Commentaires

Vous avez un commentaire ? Dites-nous tout.